================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Saturday, June 27, 2026 - 9:05 PM EDT ================================================================ The FBI and CISA warn that Russian intelligence phishing now harvests Signal Backup Recovery Keys to seize victims' full message history, as attackers separately weaponize AI coding agents and race federal patch deadlines on Cisco gear. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Russian intelligence now phishes Signal users out of their Backup Recovery Keys while the Mirage2FA kit serves fake Microsoft 365 logins to defeat multi-factor prompts. see: Russian Intelligence Targets Signal Backup Keys; Mirage2FA Phishing Kit Targets Microsoft 365 * [TREND] Active exploitation and tight federal deadlines collide on enterprise infrastructure as CISA orders a CVE-2026-20230 fix for Cisco Unified CM while Synology patches critical MailPlus Server flaws. see: Cisco Unified CM Patch Deadline; Synology MailPlus Server Flaws * [TREND] Skeptics question AI's substance as a clean GitHub repo quietly subverts coding agents, Zitron derides cargo-cult hype, and Newport pans doom-trolling even as Figma's Field stays bullish. see: Clean Repos Trick AI Coding Agents; Cargo Culture; Dear AI Companies: Stop the "Doom Trolling"; An Interview with Figma CEO Dylan Field About Design and AI * [UPDATE (new)] The Pentagon is investigating the Dialog data exposure after leaked records surfaced a senior White House intelligence official and an active-duty special operator. see: Pentagon Probes Dialog Data Exposure * [UPDATE (new)] The United States struck targets inside Iran for a second straight day, following Tehran's drone assault on Bahrain and a tanker attack in the Strait of Hormuz. see: U.S. Strikes Iran for a Second Day SECURITY ---------------------------------------------------------------- 1. CLEAN REPOS TRICK AI CODING AGENTS AI Security · [ai, supply-chain] Latest developments: BleepingComputer reported June 27 that a benign-looking GitHub repository can hide a payload an agentic coding tool runs while cloning and setting it up, staying invisible to security scanners, AI agents, and human reviewers, while threat actors separately spin up fake OpenAI tenants impersonating real companies and invite employees to join, fishing for sensitive data inside chats and projects. As developers hand setup and coding work to autonomous AI agents, attackers plant malicious instructions in trusted-looking repositories and impersonate AI vendors to harvest corporate data; teams should sandbox agent execution and verify any organization invite before joining. - BleepingComputer: https://www.bleepingcomputer.com/news/security/clean-github-repo-tricks-ai-coding-agents-into-running-malware/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/cybersecurity-firms-targeted-by-fraudulent-openai-organization-invites/ 2. RUSSIAN INTELLIGENCE TARGETS SIGNAL BACKUP KEYS Nation-State Activity · [apt, phishing] Latest developments: The FBI and CISA updated their March 2026 advisory on June 26, warning that the Russian intelligence phishing campaign against Signal users adds a step, coaxing targets into surrendering their Signal Backup Recovery Key so attackers can restore the account backup, read private and group message history, and hold persistent access. Russian intelligence services run ongoing phishing against the messaging accounts of government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States; the recovery key keeps working after theft, so affected Signal users should rotate keys and re-secure linked devices. - BleepingComputer: https://www.bleepingcomputer.com/news/security/fbi-russian-hackers-now-target-signal-backup-recovery-keys/ - The Hacker News: https://thehackernews.com/2026/06/fbi-warns-russian-intelligence-hackers.html - CISA Advisories: https://www.cisa.gov/resources-tools/resources/russian-intelligence-services-continue-target-commercial-messaging-applications 3. CISCO UNIFIED CM PATCH DEADLINE Vulnerabilities and Exploits · [patch, zero-day] Latest developments: CISA on June 26 gave federal agencies until Sunday, June 28, to patch CVE-2026-20230, a server-side request forgery flaw in Cisco Unified Communications Manager Server that attackers are actively exploiting. The Cisco Unified CM flaw lets automated Tor sweeps drop webshells on exposed servers; administrators across government and enterprise should apply Cisco's fix at once rather than wait for the federal deadline. - BleepingComputer: https://www.bleepingcomputer.com/news/security/cisa-sets-urgent-deadline-to-fix-cisco-flaw-exploited-in-attacks/ 4. SYNOLOGY MAILPLUS SERVER FLAWS Vulnerabilities and Exploits · [patch, vulnerability] Latest developments: Synology issued critical fixes June 26 for three MailPlus Server flaws, including CVE-2026-13136 from faulty authorization checks and CVE-2026-13135 from improper channel restriction, that let remote attackers read or write arbitrary files and trigger denial of service. MailPlus Server runs private email infrastructure on Synology NAS devices; administrators should install the security update immediately to close the remote file-access and denial-of-service paths. - Help Net Security: https://www.helpnetsecurity.com/2026/06/26/synology-mailplus-server-vulnerabilities/ 5. PENTAGON PROBES DIALOG DATA EXPOSURE Data Breaches · [breach, policy] Latest developments: Wired reported June 26 that the Pentagon is investigating the Dialog data exposure after leaked records from the private group surfaced the personal information of a senior White House intelligence official and an active-duty special operations officer. Exposed records from Dialog, a private group, revealed identifying details of sitting national security personnel, raising concern that the leak could unmask officials and operatives; the Defense Department is assessing the damage. - Wired Security: https://www.wired.com/story/the-pentagon-is-looking-into-the-dialog-data-exposure-for-unmasking-national-security-officials/ 6. MIRAGE2FA PHISHING KIT TARGETS MICROSOFT 365 Ransomware and Cybercrime · [phishing, credential-theft] Latest developments: Fortra detailed Mirage2FA, a phishing kit that pairs short-lived HTML smuggling with obfuscated JavaScript loaders to serve fake Microsoft 365 login pages and steal credentials during multi-factor prompts. Mirage2FA reaches victims through business-themed email lures carrying HTML and JavaScript attachments, then captures Microsoft 365 credentials mid-authentication; defenders should block HTML-smuggling attachments and enforce phishing-resistant MFA. - Help Net Security: https://www.helpnetsecurity.com/2026/06/26/mirage2fa-phishing-kit-microsoft-365-html-smuggling/ BUSINESS AND POLITICS ---------------------------------------------------------------- * U.S. Strikes Iran for a Second Day Latest developments: The United States hit multiple targets inside Iran on June 27, a second straight day of strikes that followed Tehran's drone assault on Bahrain and its attack on a tanker in the Strait of Hormuz a day earlier. The escalating tit-for-tat threatens the preliminary ceasefire President Trump signed with Tehran, and U.S. crude futures climbed back above $70 a barrel as shipping through the Strait of Hormuz stayed a flashpoint for the global economy. - FT World: https://www.ft.com/content/5f4cd16c-fa4a-4806-94ce-84df6f51ecc0 - WSJ World News: https://www.wsj.com/world/middle-east/mideast-fighting-widens-with-attacks-on-bahrain-hormuz-tanker-30a313a8 - WSJ Markets: https://www.wsj.com/finance/commodities-futures/oil-futures-fall-on-likely-technical-correction-93e57fe0?mod=rss_markets_main PITTSBURGH ---------------------------------------------------------------- Weather: Tonight: Scattered Rain Showers then Widespread Fog, low 67F. Sunday: Widespread Fog then Scattered Showers And Thunderstorms, high 85F. Sunday Night: Scattered Showers And Thunderstorms then Partly Cloudy, low 67F. Around town: * Heat Wave Brings Code Red Through July 1 Latest developments: Allegheny County confirmed June 27 that its code red heat advisory runs Monday June 29 through Wednesday July 1, when temperatures will top 90 degrees. The county Department of Human Services will check on older residents through home-delivered-meals drivers and care managers, and Pittsburgh will open cooling centers as the region heads into a multi-day heat wave. - KDKA: https://www.cbsnews.com/pittsburgh/news/allegheny-county-code-red-heat-advisory-high-temperatures/ - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/weather-news/2026/06/27/pittsburgh-thunderstorm-heat-wave-cooling-centers/stories/202606270038 * East End Food Co-op Rejects Israel Boycott Latest developments: A June 27 TribLive op-ed by Rabbi Seth Adelson recounted the East End Food Co-op board's June 15 vote against boycotting the Israeli products on its shelves. The East End Food Co-op, the member-owned grocery in Pittsburgh's East End, declined to pull its handful of Israeli products, ending a member campaign to remove them. - TribLive: https://triblive.com/opinion/rabbi-seth-adelson-failure-of-east-end-food-co-op-boycott-a-victory/ SPORTS ---------------------------------------------------------------- Pirates (41-42) Fri Jun 26 · Reds 6 · Pirates 4 · Final Marte's tiebreaking homer in 8th after 4-run inning against Skenes helps Reds beat Pirates 6-4 https://plaintextsports.com/mlb/2026-06-26/cin-pit Sat Jun 27 · Reds 9 · Pirates 7 · Final Eugenio Suárez hits 3-run homer in 9th as Reds rally for 9-7 win over Pirates https://plaintextsports.com/mlb/2026-06-27/cin-pit Up Next · Reds @ Pirates · Sun Jun 28, 1:35 PM https://plaintextsports.com/mlb/2026-06-28/cin-pit Around the Teams: * Griffin, Rodriguez Enter Labor Debate Latest developments: A June 27 Post-Gazette "Off The Bat" column laid out how the MLB Players Association can point to Pirates prospects Konnor Griffin and Endy Rodriguez in the next round of collective-bargaining fights. The column uses Griffin and Rodriguez as test cases in the union's arguments over service time and pay with Major League Baseball ahead of the next labor deal. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/06/27/mlb-labor-situation-endy-rodriguez-konnor-griffin-paul-skenes/stories/202606270013 Team USA: * USMNT Draws Bosnia in Round of 32 Latest developments: With the group stage closing June 27, the United States, winners of Group D, will open the World Cup round of 32 against Bosnia and Herzegovina. The Guardian mapped Mauricio Pochettino's path through the tournament the Americans co-host with Canada and Mexico, figuring they would likely have to beat Spain, France, and England to lift the trophy. - Guardian World Cup 2026: https://www.theguardian.com/football/2026/jun/27/usa-bracket-world-cup-path-to-final * Ranch Dressing and McKennie Win Fans Over Latest developments: ESPN wrote June 27 that international visitors have embraced American ranch dressing, vindicating U.S. midfielder Weston McKennie, whose "Love Ranch" celebration once drew mockery. Ranch has spread through World Cup memes, reels, and fans' carry-ons across the host cities, turning a running joke about McKennie into a marker of how the tournament has warmed to American tastes. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49190854/world-cup-fans-vindicate-usmnt-weston-mckennie-love-ranch-american-dressing READING ---------------------------------------------------------------- * Ed Zitron -- Cargo Culture Zitron argues the AI industry has adopted the rituals and trappings of a successful technology while lacking the underlying substance, mimicking the form of a boom rather than producing real value. https://www.wheresyoured.at/cargo-culture/ * Stratechery -- An Interview with Figma CEO Dylan Field About Design and AI Ben Thompson interviews Figma chief executive Dylan Field on how he built the design platform and why he believes AI works as a tailwind rather than a threat to the company. https://stratechery.com/2026/an-interview-with-figma-ceo-dylan-field-about-design-and-ai/ * Cal Newport -- Dear AI Companies: Stop the "Doom Trolling" Newport contends that AI firms undercut their own credibility by publicly warning their products may be dangerous, likening it to Ford fretting that its F-150 is alarming, and urges them to stop. https://calnewport.com/dear-ai-companies-stop-the-doom-trolling/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,381.60 ▼ -1.4% Dow 51,805.04 ▲ +0.4% Nasdaq 25,577.30 ▼ -2.7% WTI crude 71.90 ▼ -9.0% EUR/USD 1.1382 ▼ -1.3% GBP/USD 1.3200 ▼ -0.8% USD/JPY 161.68 ▲ +0.6% ================================================================ Generated 2026-06-27 21:05 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================